Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,432cataloged exploits
34,424CVEs with public exploitation
24,695lab-tested
75,432 exploits
GitHub PoC
Baza-NATO/CVE-2021-33044
CVE-2021-33044CRITICALunder attack25 Jan 2026
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RISK
open
GitHub PoC
jagg3rsec/CVE-2014-6287
CVE-2014-6287CRITICALunder attack25 Jan 2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISK
open
GitHub PoC1
A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.
CVE-2021-21311HIGHunder attack24 Jan 2026
SSRF in adminer
100RISK
open
GitHub PoC
xitexploiter96-dot/CVE-2023-38408
CVE-2023-38408CRITICAL24 Jan 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2023-38408CRITICAL24 Jan 2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RISK
open
GitHub PoC
ranasen-rat/cve-2021-42013
CVE-2021-42013CRITICALunder attackransomware24 Jan 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC
For HTB practice
CVE-2022-44268MEDIUM24 Jan 2026
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALunder attack24 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack24 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-24061CRITICALunder attack24 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
info-leak
CVE-2026-24061CRITICALunder attack24 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
client-side
CVE-2021-42013CRITICALunder attackransomware24 Jan 2026
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack23 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack23 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack23 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
VulnCheck XDB
initial-access
CVE-2026-24061CRITICALunder attack23 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC2
Sairbo/Unihackers---CVE-2025-55182-
CVE-2025-55182CRITICALunder attackransomware23 Jan 2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RISK
open
GitHub PoC
CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.
CVE-2025-52691CRITICALunder attackransomware23 Jan 2026
Upload Arbitrary Files
100RISK
open
VulnCheck XDB
initial-access
CVE-2025-2294CRITICAL23 Jan 2026
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
GitHub PoC2
The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via the `kubio_hybrid_theme_load_template` function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files..
CVE-2025-2294CRITICAL23 Jan 2026
Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
85RISK
open
VulnCheck XDB
initial-access
CVE-2025-52691CRITICALunder attackransomware23 Jan 2026
Upload Arbitrary Files
100RISK
open
GitHub PoC
Replica of CVE-2019-15715 in Python3
CVE-2019-1571523 Jan 2026
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
35RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2026-23760CRITICALunder attackransomware23 Jan 2026
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISK
open
GitHub PoC6
Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers to gain instant root shell access via malicious NEW_ENVIRON telnet option exploitation.
CVE-2026-24061CRITICALunder attack23 Jan 2026
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RISK
open
GitHub PoC1
A hands-on project demonstrating the setup of virtual security lab, network reconnaissance, and exploitation of CVE-2012-1823.
CVE-2012-1823CRITICALunder attack22 Jan 2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISK
open
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2024-51793. Exploits an arbitrary file upload vulnerability via admin-ajax.php to upload a PHP payload and achieve remote command execution on vulnerable WordPress installations, including OS detection and an interactive command shell.
CVE-2024-51793CRITICAL22 Jan 2026
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
48RISK
open
GitHub PoC
Dirty Cow exploit - CVE-2016-5195
CVE-2016-5195HIGHunder attack22 Jan 2026
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISK
open
GitHub PoC
Relatório TryHackMe — n8n CVE-2025-68613 (CVSS 9.9)
CVE-2025-68613CRITICALunder attack22 Jan 2026
n8n Vulnerable to Remote Code Execution via Expression Injection
100RISK
open
GitHub PoC2
Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to upload a remote PHP payload, detect the target operating system, and achieve remote command execution through an interactive web shell.
CVE-2024-9932CRITICAL22 Jan 2026
Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
60RISK
open
GitHub PoC1
Unauthenticated 0-click RCE exploit for CVE-2023-51409. Abuses an arbitrary file upload flaw in the AI Engine WordPress plugin to upload a PHP webshell and achieve remote command execution without authentication, including OS detection and an interactive shell.
CVE-2023-51409CRITICAL22 Jan 2026
WordPress AI Engine plugin <= 1.9.98 - Unauthenticated Arbitrary File Upload vulnerability
75RISK
open
previouspage 135 / 2,515next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.